> Source: [sk184604](https://support.checkpoint.com/results/sk/sk184604)

# sk184604 - Check Point plans for TLS Certificate Lifetime Reduction

| Property | Value |
|----------|-------|
| Solution ID | sk184604 |
| Date Created | 2026-01-28 |
| Last Modified | 2026-04-05 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.20 |

## Solution

### Industry-Mandated TLS Certificate Lifetime Reduction

<br />

The transition to a 47-day maximum validity period for publicly trusted SSL/TLS certificates is a mandatory, industry-wide change that will take full effect on March 15, 2029. This decision was approved by the CA/Browser (CA/B) Forum and is being enforced by major browser vendors.  

The change is being introduced gradually through a series of mandatory reductions to allow organizations time to adapt. Its primary objectives are to strengthen web security and to accelerate the adoption of automated certificate lifecycle management.  

The reduction in certificate lifetime is intended to improve the overall security and resilience of the web PKI ecosystem. Improvements include:  

* Reduced attack window: In the event of private key compromise, the exposure period is significantly shortened.
* Improved cryptographic agility: More frequent renewals ensure faster adoption of updated security standards and cryptographic algorithms.
* Enforced automation: Manual certificate renewal at a 47-day cadence is not operationally viable, driving organizations toward automated certificate lifecycle management and reducing the risk of human error and service outages.

The current maximum certificate lifetime of **398** days will be reduced as follows:  

From **March 15, 2026** : Maximum lifetime reduced to **200** days  
From **March 15, 2027** : Maximum lifetime reduced to **100** days  
From **March 15, 2029** : Maximum lifetime reduced to **47** days  

For more information, see [the relevant decision of the CA/Browser Forum](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods/).   

### **Impact on** Check **Point Customers**

<br />

Check Point is closely monitoring the industry-wide transition toward shorter lifetimes for publicly trusted TLS certificates. While this shift enhances security, we recognize the significant operational challenges it introduces.  

The move to short-lived certificates dramatically increases the frequency of certificate lifecycle tasks. Without automation, this transition places a heavy burden on administrators, as manual management does not scale and significantly increases the risk of service outages if not properly addressed.  

These changes impact customers using publicly trusted certificates issued by third-party Certificate Authorities (Cas) that adhere to the updated industry requirements. Affected use cases include, but are not limited to:  

* Inbound HTTPS inspection
* Web-based management and service portals (for example: Mobile Access Portal, UserCheck, and other multi-portal websites)
* Additional products and flows that rely on externally issued TLS certificates

Examples of use cases that are **not** affected:  

* Outbound HTTPS inspection
* Certificates issued by Check Point Internal Certificate Authorities (e.g., SIC certificates
* Default VPN certificates and other internally managed certificates

<br />

### Check Point's Plan to Address the Change

<br />

To mitigate these operational risks, Check Point is developing a suite of enhancements designed to automate certificate management and ensure service continuity.  

**Planned Improvements**   

* Zero-Downtime Certificate Renewal: The ability to replace certificates without a policy installation, eliminating downtime and operational maintenance windows.
* ACME Protocol Integration: Full support for the ACME protocol to enable automated certificate enrollment and renewal.
* Proactive Automatic Certificate Renewal: Automatic certificate renewal prior to certificate expiration, ensuring service continuity and reducing the risk of disruption

<br />

**Delivery Timeline**   

The majority of these automation enhancements are scheduled for a 2027 release.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
